KEMETIC MINDS
Infrastructure Watch — Daily Update — August 06, 2026

Good morning. A new scan found 4,400 internet-connected industrial controllers used in water systems still exposed online — including 22 in cities already targeted — even as the FBI and EPA confirm attacks in at least 12 states since July 27 (CyberScoop, 2026). Axios, cited by NJBIZ, calls the wave “one of the broadest known coordinated cyber campaigns against U.S. municipal water systems to date” (NJBIZ, 2026).
Key Takeaways
- A Forescout Vedere Labs scan found 4,400 exposed PLCs — 2,844 (65%) in the U.S., including 22 in cities recently hit by water-system attacks (CyberScoop, 2026).
- The FBI and EPA confirmed attacks at water and wastewater utilities in at least 12 states since July 27 (CyberScoop, 2026).
- New Jersey said at least two municipal water systems were targeted in the past week, with both shifting to manual operations (NJBIZ, 2026).
- Minnesota confirmed more than 30 community water systems were targeted on July 26-27 (Eastern Echo, 2026).
- Michigan’s Ypsilanti Community Utilities Authority said it was not impacted, and state officials said all systems operated safely (Eastern Echo, 2026).
- Data center outage frequency is down, but 57% of recent major outages cost more than $100,000 (TechRepublic, 2026).
“industrial controllers used in water systems remain exposed online A scan of internet-connected industrial equipment found 4,400 exposed PLCs, including 22 in cities recently targeted by water system attacks.”
CyberScoop —
Read the full report →
1. Water Supply: Exposed Controllers, Expanding Attack Wave
The exposure numbers are stark. Forescout’s Vedere Labs, scanning via Shodan on Monday and publishing Wednesday, found 4,400 exposed PLCs — 2,844 of them (65%) in the United States, including 22 in cities impacted by recent cyberattacks on water systems (CyberScoop, 2026). The scan also identified over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online; with the EtherNet/IP port open to the public internet, outside users may be able to identify devices and, depending on setup, change settings or write new configurations — exposure that persists despite years of warnings from manufacturers and federal agencies (CyberScoop, 2026).
The FBI and EPA issued a joint advisory last week confirming attacks at water and wastewater utilities in at least 12 states since July 27, and officials have since named Michigan, South Dakota and Georgia (CyberScoop, 2026). OFFGRID Survival is now headlining “Twelve States Now Hit.” At least two municipal water systems in New Jersey were reportedly targeted in the past week, with NJOHSP saying the incidents temporarily disabled automated systems that help monitor and operate water infrastructure before both utilities shifted to manual operations; the agency said both systems “have since been secured with strengthened access controls” and that the NJCCIC continues working with utilities statewide (NJBIZ, 2026).
State-level reporting shows an uneven picture. Michigan’s Ypsilanti Community Utilities Authority said it was not among the impacted systems, and EGLE communications officials said “all systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern” (The Eastern Echo, 2026). Minnesota’s state government confirmed more than 30 community water systems were targeted July 26-27, and the FBI’s July 30 PSA said attackers targeted specific devices across at least seven states, with reports of flooding and water pressure loss — the latter flagged as a contamination risk (Eastern Echo, 2026).
Attribution remains unresolved. A previous April 7 joint statement from the EPA, FBI, CISA and NSA warned about similar water-system attacks from Iran-affiliated actors, but the Michigan State Police — which said it is working with federal partners to monitor the situation — did not answer who is behind the current wave (Eastern Echo, 2026).
“All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern,”
The Eastern Echo —
Read the full report →
2. Power Supply: Data Center Outages Less Frequent, Costlier
On the power-reliability front, Uptime Institute’s eighth annual outage analysis finds data center outage frequency has declined for five straight years on a per-site basis — welcome news where even a brief cooling interruption can force GPU systems to throttle or shut down (TechRepublic, 2026). But the cost of failure keeps climbing: 57% of respondents said their most recent major outage cost more than $100,000, and one in five said costs exceeded $1 million (TechRepublic, 2026).
“Outages overall have slowed down, and overall, digital infrastructure is remarkably resilient. But further resiliency gains are becoming harder to achieve,” said Andy Lawrence, founding member and executive director of Uptime Intelligence, who added that failures will increasingly be linked to complex interactions across software, networks and external dependencies rather than a single point of failure (TechRepublic, 2026).
Uptime also reports that external infrastructure failures have become more prominent in publicly reported outages, pointing to fiber- and connectivity-related issues that can cause extended disruptions, and warns that AI workload growth will place greater demands on network performance. Rising costs are attributed partly to inflation, labor and hardware costs, service-level agreement penalties and longer recovery times (TechRepublic, 2026).
What’s Disputed or Unconfirmed
The state count is inconsistent across sourcing: CyberScoop reports federal confirmations of attacks in at least 12 states, while The Eastern Echo attributes a figure of at least seven states to the FBI’s July 30 PSA — a gap the available reporting does not reconcile (CyberScoop, 2026; Eastern Echo, 2026). The CyberScoop article also truncates after naming Michigan, South Dakota and Georgia, so the full list of states identified by officials is not yet clear (CyberScoop, 2026).
New Jersey’s disclosure is limited: NJOHSP did not identify the two affected utilities, and NJBIZ describes the systems as “reportedly targeted” (NJBIZ, 2026). Attribution for the current wave is officially unstated — the Iran-affiliated warning dates to the earlier April advisory (Eastern Echo, 2026). The OFFGRID Survival headline corroborates the 12-state tally, but its article text was not available in the fetched source, so it should be treated as secondary confirmation only (OFFGRID Survival, 2026).
Kemetic Minds Analysis
Today’s verified reporting covered: Water Supply; Power Supply. Every claim above traces back to a specific, dated, fetched source — treat the Key Takeaways as the verified factual floor, and the ‘What’s Disputed or Unconfirmed’ section as the honest boundary of what today’s sourcing actually supports versus what’s still allegation or one-sided claim. The two checklists below are static, agency-sourced preparedness guidance (FEMA/Ready.gov/CDC/USDA) and are not tied to today’s specific stories.
🛡️ Free Preparedness Guides
Two free, printable checklists you can download and keep on hand — one for water-supply
disruptions, one for power outages.
📄 Get this checklist as a free, printable PDF you can keep on hand.
📄 Get this checklist as a free, printable PDF you can keep on hand.
References
- CyberScoop. (2026, August 6). Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online. cyberscoop.com
- The Eastern Echo. (2026, August 6). Ypsilanti water systems not impacted amid multi-state cyber attacks. easternecho.com
- NJBIZ. (2026, August 6). Cyberattack targets 2 NJ municipal water systems (updated). njbiz.com
- OFFGRID Survival. (2026, August 6). Hackers Hit New Jersey Water Systems: Twelve States Now Hit in attack on America’s Drinking Water. offgridsurvival.com
- Techrepublic. (2026, August 6). Data Center Outages Are Less Frequent but More Expensive, Uptime Finds. techrepublic.com
Investigative Methodology: This roundup is generated once daily at 5:00 PM America/Chicago from live news sources published within the prior 24 hours. Every claim is grounded in fetched source text with an APA7 in-text citation; nothing is written from the model’s general knowledge. Every video embed is verified to be a real, existing video via YouTube’s oEmbed endpoint, published within the last 24 hours, and restricted to a credible-outlet allowlist before publication — none are written by the drafting model. Pull-quotes are extracted verbatim from the cited article, never composed. The preparedness checklists are static guidance sourced from FEMA/Ready.gov, the CDC, and the USDA, never generated by the drafting model, and are not medical, legal, or emergency-response advice.
Stay Connected

